Apple has released Security Update 2015-003 1.0 for OS X Yosemite 10.10.2.
The update address an issue with iCloud Keychain and IOSurface.
—
Security Update 2015-003
iCloud Keychain
● Available for: OS X Yosemite v10.10.2
● Impact: An attacker with a privileged network position may be able to execute arbitrary code
● Description: Multiple buffer overflows existed in the handling of data during iCloud Keychain recovery. These issues were addressed through improved bounds checking.
● CVE-2015-1065 : Andrey Belenko of NowSecure
IOSurface
● Available for: OS X Yosemite v10.10.2
● Impact: A malicious application may be able to execute arbitrary code with system privileges
● Description: A type confusion issue existed in IOSurface’s handling of serialized objects. The issue was addressed through additional type checking.
● CVE-2015-1061 : Ian Beer of Google Project Zero
Recent Comments